Ransomware victim disclosure
← All victimsFerrosider Componentes
listed as grupoferrosider.com.br · Claimed by Lockbit5 · listed 4 months ago
Status timeline
- ListedFeb 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Brazil
- Sector
- Manufacturing
- Listed on leak site
- Feb 7, 2026
About the victim
AI dossier — public-source company profileFerrosider Componentes is a Brazilian manufacturer and supplier of automotive parts and steel components, including welded carbon steel tubes, steel sheets and coils, and protective bars. Founded in 1991 and headquartered in Contagem, Minas Gerais, the company holds IATF 16949:2016 certification and serves the metalworking and automotive industries. The company reports over 30 years of experience and more than 500 completed projects.
- Industry
- Automotive Parts & Steel Components Manufacturing
- Address
- R. Sebastião Viana, 80 - Cincao, Contagem/MG - 32371-640, Brazil
- Founded
- 1991
Attack summary
Severity: high — The disclosure status is 'data_published', meaning the ransomware group has already released data, confirming exfiltration of significant business data from a manufacturing company with LGPD-regulated personal data obligations.The LockBit 5 ransomware group claims to have attacked Ferrosider Componentes and has disclosed the data (status: data_published), indicating exfiltration and/or encryption of company data. No ransom amount or specific data volume has been stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Automotive parts and components business data
- Corporate/administrative records
- Potentially customer and partner information
- Potentially employee records
What the group claims
Ferrosider Componentes is a leading provider of automotive parts and components designed for the met...
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

